logo

Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite

ID: ee47c64a-bc39-5dfb-a032-ec93add1a621

STIX ID: report--ee47c64a-bc39-5dfb-a032-ec93add1a621

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2025-12-11

Date Updated: 2026-04-28

Author: Unit 42

...
...

Unit42 details a long‑running espionage campaign by the Hamas‑affiliated APT 'Ashen Lepus' using a new modular .NET malware suite called AshTag to target government and diplomatic entities across the Middle East; the report describes a multi‑stage infection chain (RAR decoys, side‑loaded loaders and stagers, AshenOrchestrator), in‑memory execution, C2 evasion via legitimate subdomains and embedded HTML payloads, observed hands‑on theft and exfiltration (including use of Rclone), and provides numerous IOCs (SHA256 hashes, AES keys/nonce, C2 domains, and scheduled task names) plus mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.